CVE-2013-1060 REJECTED

A certain Ubuntu build procedure for perf, as distributed in the Linux kernel packages in Ubuntu 10.04 LTS, 12.04 LTS, 12.10, 13.04, and 13.10, sets the HOME environment variable to the ~buildd directory and consequently reads the system configuration file from the ~buildd directory, which allows local users to gain privileges by leveraging control over the buildd account.

EPSS 0.05% · 15.6th percentile

Risk Scores

EPSS Score
0.05%
15.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-raspi20
Ubuntu:16.04:LTSlinux-oem0
Ubuntu:16.04:LTSlinux-gke0
Ubuntu:16.04:LTSlinux-aws0
Ubuntu:14.04:LTSlinux-aws0
Ubuntu:16.04:LTSlinux-kvm0
Ubuntu:16.04:LTSlinux-azure0
Ubuntu:14.04:LTSlinux-lts-utopic0
Ubuntu:16.04:LTSlinux-hwe0
Ubuntu:16.04:LTSlinux-snapdragon0
Ubuntu:16.04:LTSlinux-euclid0
Ubuntu:14.04:LTSlinux-lts-xenial0
Ubuntu:14.04:LTSlinux-azure0
Ubuntu:16.04:LTSlinux-gcp0
Ubuntu:14.04:LTSlinux0
Ubuntu:14.04:LTSlinux-lts-wily0
Ubuntu:14.04:LTSlinux-lts-vivid0
Ubuntu:16.04:LTSlinux0

Timeline

References

Open in Interactive Console →